ICQ vulnerable to account theft - Update
In security advisories for ICQ and the ICQ web site, security researcher Levent Kayan warns that both the ICQ instant messenger for Windows and the ICQ web site contain vulnerabilities that potentially allow attackers to take control of a user's ICQ account. According to Kayan ICQ doesn't adequately check user's profile information and fails properly to analyse status messages, which can be freely chosen by users, to see if they contain executable code. Kayan recently discovered a similar hole in the Skype client.
Update: ICQ's PR company has told heise Security that the developers have identified the problem and are "well on the way" to fixing it.